diff --git a/ChangeLog b/ChangeLog index e1a510ea..f7ef95ac 100644 --- a/ChangeLog +++ b/ChangeLog @@ -40,6 +40,7 @@ ver. 0.8.12 (2013/12/XX) - things-can-only-get-better - updated check_fail2ban to return performance data for all jails. - filter apache-noscript now includes php cgi scripts. Thanks dani. Closes gh-503 + - added ufw action. Thanks Guilhem Lettron. lp-#701522 - New Features: diff --git a/THANKS b/THANKS index 7e97c04c..1919263e 100644 --- a/THANKS +++ b/THANKS @@ -35,6 +35,7 @@ ftoppi François Boulogne Frédéric Georgiy Mernov +Guilhem Lettron Guillaume Delvit Hanno 'Rince' Wagner Iain Lea diff --git a/config/action.d/ufw.conf b/config/action.d/ufw.conf new file mode 100644 index 00000000..c826729d --- /dev/null +++ b/config/action.d/ufw.conf @@ -0,0 +1,40 @@ +# Fail2Ban action configuration file for ufw +# +# You are required to run "ufw enable" before this will have an effect. +# +# The insert position should be approprate to block the required traffic. +# A number after an allow rule to the application won't be much use. + +[Definition] + +actionstart = + +actionstop = + +actioncheck = + +actionban = [ -n "" ] && app="app " ; ufw insert from to $app + +actionunban = [ -n "" ] && app="app " ; ufw delete from to $app + +[Init] +# Option: insertpos +# Notes.: The postition number in the firewall list to insert the block rule +insertpos = 1 + +# Option: blocktype +# Notes.: reject or deny +blocktype = reject + +# Option: destination +# Notes.: The destination address to block in the ufw rule +destination = any + +# Option: application +# Notes.: application from sudo ufw app list +application = + +# DEV NOTES: +# +# Author: Guilhem Lettron +# Enhancements: Daniel Black